atlassian-353a14 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited atlassian-353a14 (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<p align="center"> <img src="images/atlassian_logo_brand_RGB.svg"> </p>
The Atlassian Rovo MCP Server is a cloud-based bridge between your Atlassian Cloud site and compatible external tools. Once configured, it enables those tools to interact with Jira, Compass, and Confluence data in real-time. This functionality is powered by secure authentication using OAuth 2.1 or API tokens, which ensures all actions respect the user's existing access controls.
With the Atlassian Rovo MCP Server, you can:
It's designed developers, content creators, and project teams who use IDEs or AI platforms and want to work with Atlassian data without constantly context switching.
The Atlassian Rovo MCP Server supports several clients, including:
The Atlassian Rovo MCP Server also supports any local MCP-compatible client that can run on localhost and connect to the server via the mcp-remote proxy. This enables custom or third-party integrations that follow the MCP specification.
For detailed setup instructions, refer to your client's own MCP documentation or built-in assistant.
Ensure your environment meets the necessary requirements to successfully set up the Atlassian Rovo MCP Server. This section outlines the technical prerequisites and key access considerations.
Before connecting to the Atlassian Rovo MCP Server, review the setup requirements for your environment:
#### For supported clients
#### For IDEs or local clients (Desktop setup)
mcp-remote)Security is a core focus of the Atlassian Rovo MCP Server:
For a deeper overview of the security model and admin controls, see:
https://mcp.atlassian.com/v1/mcp[!NOTE] While/sseas a server endpoint are supported, we recommend updating any custom clients configured to use/sseso they now point to/mcp.
Access is granted only to data that the user already has permission to view in Atlassian Cloud. All actions respect existing project or space-level roles. OAuth and API token authentication both honor configured scopes and Atlassian permissions.
API token authentication is available for headless or long-running client setups.
Once connected, you can perform a variety of useful tasks from within your supported client.
api-gateway service?"[!NOTE] Actual capabilities vary, depending on your permission level and client platform.
Update your AGENTS.md with the Markdown below to reduce discovery tool calls, save time and tokens, and set maximum search results.
## Atlassian Rovo MCP
When connected to atlassian-rovo-mcp:
- **MUST** use Jira project key = YOURPROJ
- **MUST** use Confluence spaceId = "123456"
- **MUST** use cloudId = "https://yoursite.atlassian.net" (do NOT call getAccessibleAtlassianResources)
- **MUST** use `maxResults: 10` or `limit: 10` for ALL Jira JQL and Confluence CQL search operations.If you're using a desktop client like Claude, you can create or reuse skills for repeated tasks. See the default Rovo MCP skills
For Cursor, skills are part of the marketplace plugin.
If you're an admin preparing your organization to use the Atlassian Rovo MCP Server, review these key considerations. For more detailed admin guidance, see:
The Atlassian Rovo MCP Server is _not_ installed via the Atlassian Marketplace or the Manage apps screen. Instead, it is installed automatically the first time a user completes the OAuth 2.1 (3LO) consent flow (just-in-time or "lazy loading" installation).
The first user to complete the 3LO consent flow for your site must have access to the Atlassian apps requested by the MCP scopes (for example, Jira and/or Confluence). This ensures the MCP app is registered with the correct permissions for your site.
After the initial install, users with access to only one Atlassian app (for example, just Jira or just Confluence) can also complete the 3LO flow to access that Atlassian app through MCP.
Site and organization admins can manage, review, or revoke the MCP app's access from Manage your organization's Marketplace and third-party apps. The app appears in your site's Connected apps list after the first successful 3LO consent.
Individual users can revoke their own app authorizations from their profile settings.
Use the Rovo MCP server settings page in Atlassian Administration to control which external AI tools and domains are allowed to connect. For details, see Available Atlassian Rovo MCP server domains. If your organization uses IP allowlisting for Atlassian Cloud apps, requests made through the Atlassian Rovo MCP Server must originate from an IP address that is allowed by your organization's IP allowlist for the relevant Atlassian app. For configuration details, see Specify IP addresses for app access.
A site admin must complete the 3LO consent flow before anyone else can use the MCP app. See "Your site admin must authorize this app" error in Atlassian Cloud apps for more details.
This usually indicates that IP allowlisting is enabled and the user's current IP address isn't allowed to access Jira, Confluence, Compass, or Rovo via the Atlassian Rovo MCP Server. Ask your site or organization admin to review the IP allowlist configuration and add the relevant network or VPN IP ranges if appropriate.
Ensure the user is using the correct Atlassian account and site, and confirm the app is requesting the correct Atlassian app scopes (for example, Jira scopes). If issues persist, check Manage your organization's Marketplace and third-party apps or contact Atlassian Support. Also verify the user's Jira, Confluence, or Compass permissions in Atlassian Administration.
Model Context Protocol (MCP) lets AI agents connect to tools and Atlassian data using your account’s permissions, which creates powerful workflows but also structural risks. Any MCP client or server you enable (e.g., IDE plugins, desktop apps, hosted MCP servers, “one-click” integrations) can cause an AI agent to perform actions on your behalf.
Large Language models (LLMs) are vulnerable to prompt injection and related attacks (such as indirect prompt injection and tool poisoning). These attacks can instruct the agent to exfiltrate data or make unintended changes without explicit requests.
To reduce risk, only use trusted MCP clients and servers, carefully review which tools and data each agent can access, and apply least privilege (scoped tokens, minimal project/workspace access). For any high‑impact or destructive action, require human confirmation and monitor audit logs for unusual activity. We strongly recommend reviewing Atlassian’s guidance on MCP risks at MCP Clients: Understanding the potential security risks
Your feedback plays a crucial role in shaping the Atlassian Rovo MCP Server. If you encounter bugs, limitations, or have suggestions:
MCP clients can perform actions in Jira, Confluence, and Compass with your existing permissions. Use least privilege, review high‑impact changes before confirming, and monitor audit logs for unusual activity.
Learn more: MCP Clients - (Understanding the potential security risks)[https://www.atlassian.com/blog/artificial-intelligence/mcp-risk-awareness]
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.